{"api_version":"1","generated_at":"2026-07-23T04:54:43+00:00","cve":"CVE-2011-1392","urls":{"html":"https://cve.report/CVE-2011-1392","api":"https://cve.report/api/cve/CVE-2011-1392.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-1392","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-1392"},"summary":{"title":"CVE-2011-1392","description":"The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and other products, does not properly implement the (1) Start, (2) PauseAndSave, (3) InsertMarker, and (4) InsertSoundToFBRAtMarker methods, which allows remote attackers to execute arbitrary code via unspecified vectors.","state":"PUBLISHED","assigner":"mitre","published_at":"2011-12-23 22:55:00","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-94","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://secunia.com/advisories/47286","name":"http://secunia.com/advisories/47286","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Alerts - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/71804","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/71804","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21576352","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21576352","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"IBM Security Bulletin: Rational Rhapsody for Windows Blueberry FlashBack ActiveX Control vulnerabilities (CVE-2011-1388, CVE-2011-1391, CVE-2011-1392) - United States","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/47310","name":"http://secunia.com/advisories/47310","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Alerts - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-1392","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-1392","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"1392","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":".bbsoftware","cpe5":"bb_flashback","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1392","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"rational_rhapsody","cpe6":"7.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1392","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"rational_rhapsody","cpe6":"7.5.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1392","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"rational_rhapsody","cpe6":"7.5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1392","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"rational_rhapsody","cpe6":"7.5.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1392","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"rational_rhapsody","cpe6":"7.5.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1392","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"rational_rhapsody","cpe6":"7.5.2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1392","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"rational_rhapsody","cpe6":"7.5.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1392","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"rational_rhapsody","cpe6":"7.5.3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1392","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"rational_rhapsody","cpe6":"7.5.3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1392","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"rational_rhapsody","cpe6":"7.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1392","vulnerable":"0","versionEndIncluding":"7.6.0.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"rational_rhapsody","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T22:21:34.769Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"47286","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/47286"},{"name":"ibm-ratth-bbfb-code-execution(71804)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/71804"},{"name":"47310","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/47310"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21576352"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-12-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and other products, does not properly implement the (1) Start, (2) PauseAndSave, (3) InsertMarker, and (4) InsertSoundToFBRAtMarker methods, which allows remote attackers to execute arbitrary code via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"47286","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/47286"},{"name":"ibm-ratth-bbfb-code-execution(71804)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/71804"},{"name":"47310","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/47310"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21576352"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2011-1392","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and other products, does not properly implement the (1) Start, (2) PauseAndSave, (3) InsertMarker, and (4) InsertSoundToFBRAtMarker methods, which allows remote attackers to execute arbitrary code via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"47286","refsource":"SECUNIA","url":"http://secunia.com/advisories/47286"},{"name":"ibm-ratth-bbfb-code-execution(71804)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/71804"},{"name":"47310","refsource":"SECUNIA","url":"http://secunia.com/advisories/47310"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21576352","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21576352"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2011-1392","datePublished":"2011-12-23T22:00:00.000Z","dateReserved":"2011-03-10T00:00:00.000Z","dateUpdated":"2024-08-06T22:21:34.769Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-12-23 22:55:00","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-94","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:.bbsoftware:bb_flashback:*:*:*:*:*:*:*:*","matchCriteriaId":"BF7911FB-D2DE-4571-A8F3-167C8DA4E2B0"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:ibm:rational_rhapsody:*:*:*:*:*:*:*:*","versionEndIncluding":"7.6.0.1","matchCriteriaId":"A7A262C5-3999-4878-8A8E-808FEA31BB69"},{"vulnerable":false,"criteria":"cpe:2.3:a:ibm:rational_rhapsody:7.5:*:*:*:*:*:*:*","matchCriteriaId":"8B5E0E9E-FF44-46BE-9BAB-4C907AE23B46"},{"vulnerable":false,"criteria":"cpe:2.3:a:ibm:rational_rhapsody:7.5.0.1:*:*:*:*:*:*:*","matchCriteriaId":"6A206B67-3D12-4BCD-9116-9AD12910E89F"},{"vulnerable":false,"criteria":"cpe:2.3:a:ibm:rational_rhapsody:7.5.1:*:*:*:*:*:*:*","matchCriteriaId":"2E147396-F813-4DD7-A492-C58538FB4926"},{"vulnerable":false,"criteria":"cpe:2.3:a:ibm:rational_rhapsody:7.5.1.1:*:*:*:*:*:*:*","matchCriteriaId":"9619D07C-FF49-499E-BD12-D550C3BEFE96"},{"vulnerable":false,"criteria":"cpe:2.3:a:ibm:rational_rhapsody:7.5.2:*:*:*:*:*:*:*","matchCriteriaId":"498C1B70-25A6-44AF-9EDC-EA396153A1C1"},{"vulnerable":false,"criteria":"cpe:2.3:a:ibm:rational_rhapsody:7.5.2.1:*:*:*:*:*:*:*","matchCriteriaId":"B72DB790-D922-4F9D-900D-F2E24FD6171F"},{"vulnerable":false,"criteria":"cpe:2.3:a:ibm:rational_rhapsody:7.5.3:*:*:*:*:*:*:*","matchCriteriaId":"E8513CB6-CB88-4350-BBF0-9B8997D6B4ED"},{"vulnerable":false,"criteria":"cpe:2.3:a:ibm:rational_rhapsody:7.5.3.1:*:*:*:*:*:*:*","matchCriteriaId":"AC6C0CF8-D4BE-4095-A552-113B681B8E30"},{"vulnerable":false,"criteria":"cpe:2.3:a:ibm:rational_rhapsody:7.5.3.2:*:*:*:*:*:*:*","matchCriteriaId":"80939055-FE60-440F-B018-6EAE05D6638E"},{"vulnerable":false,"criteria":"cpe:2.3:a:ibm:rational_rhapsody:7.6:*:*:*:*:*:*:*","matchCriteriaId":"36E9BFF1-6D25-4B51-9288-FCDB4093449B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"1392","Ordinal":"1","Title":"CVE-2011-1392","CVE":"CVE-2011-1392","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"1392","Ordinal":"1","NoteData":"The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and other products, does not properly implement the (1) Start, (2) PauseAndSave, (3) InsertMarker, and (4) InsertSoundToFBRAtMarker methods, which allows remote attackers to execute arbitrary code via unspecified vectors.","Type":"Description","Title":"CVE-2011-1392"},{"CveYear":"2011","CveId":"1392","Ordinal":"2","NoteData":"2011-12-23","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"1392","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}